Search

Found 1,303 results in 1174ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-0412 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0402 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0401 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unk…
CVE-2014-0386 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unk…
CVE-2013-5891 medium 4.0 debian debianubuntu ubuntu rhel oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related …
CVE-2013-6422 medium 4.0 FIX debian debianubuntu ubuntu haxx 13y ago The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fie…
CVE-2013-6391 medium 5.8 FIX debian debianubuntu ubuntu openstackredhat 13y ago The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to …
CVE-2012-6151 medium 5.3 EXPFIX debian debianmacos macosubuntu ubuntu net-snmp 13y ago Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, …
CVE-2013-6673 medium 5.9 5.9 fedora fedorasuse suseubuntu ubuntu mozillasuse 13y ago Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it e…
CVE-2013-6672 medium 4.3 linux-kernelfedora fedorasuse suse mozilla 13y ago Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
CVE-2013-5619 high 7.5 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-…
CVE-2013-5614 medium 4.3 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attacker…
CVE-2013-5612 medium 4.3 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Orig…
CVE-2013-5611 medium 5.8 fedora fedorasuse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing…
CVE-2013-6410 high 7.5 FIX ubuntu ubuntudebian debian wouter_verhelst 13y ago nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partia…
CVE-2013-6712 medium 5.0 macos macossuse suseubuntu ubuntu php 13y ago The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of servi…
CVE-2013-1058 medium 5.8 ubuntu ubuntu canonical 13y ago maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
CVE-2013-6858 medium 4.3 FIX debian debiansuse suseubuntu ubuntu openstack 13y ago Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" …
CVE-2013-4474 medium 6.0 EXPFIX ubuntu ubuntudebian debian freedesktop 13y ago Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in …
CVE-2013-4473 high 7.5 FIX ubuntu ubuntudebian debian freedesktop 13y ago Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c…
CVE-2010-3443 medium 5.0 FIX ubuntu ubuntudebian debian quassel-irc 13y ago ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIV…
CVE-2013-4588 high 7.0 7.0 FIX ubuntu ubuntu linux-kerneldebian debian 13y ago Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_AD…
CVE-2013-4563 high 7.1 FIX ubuntu ubuntudebian debian linux-kernel 13y ago The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly perform a certain size comparison before …
CVE-2013-6629 medium 5.0 FIX slesdebian debianfedora fedora googleartifexlibjpeg-turbo 13y ago The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain dup…
CVE-2013-1057 medium 4.4 ubuntu ubuntu canonical 13y ago Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current wo…
CVE-2013-4475 medium 4.0 FIX debian debianubuntu ubuntu samba 13y ago Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restricti…
CVE-2013-4348 high 7.1 FIX debian debian linux-kernelubuntu ubuntu 13y ago The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of …
CVE-2013-4402 medium 5.0 FIX debian debianubuntu ubuntu gnupg 13y ago The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.
CVE-2013-1067 medium 4.9 ubuntu ubuntu 13y ago Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
CVE-2013-5807 medium 4.9 rhelubuntu ubuntudebian debian oraclemariadb 13y ago Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to…
CVE-2013-3839 medium 4.0 rhelubuntu ubuntudebian debian oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unk…
CVE-2013-4256 medium 4.6 FIX ubuntu ubuntudebian debian radscan 13y ago Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a denial of service (crash) or possibly execute arbitrary code via the (1) display …
CVE-2013-2099 medium 4.3 FIX debian debianubuntu ubuntu python 13y ago Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python v…
CVE-2013-4344 high 7.2 FIX slesubuntu ubuntu rhel qemuredhat 13y ago Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a R…
CVE-2013-4327 medium 6.9 FIX ubuntu ubuntudebian debian systemd_project 13y ago systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race con…
CVE-2013-4311 medium 4.6 FIX debian debianubuntu ubuntu rhel redhat 13y ago libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race c…
CVE-2013-4288 high 7.2 FIX slesubuntu ubuntu rhel polkit_project 13y ago Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is perf…
CVE-2013-1066 medium 4.6 ubuntu ubuntu ubuntu_developers 13y ago language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass inte…
CVE-2013-1065 medium 4.6 ubuntu ubuntu martin_pitt 13y ago backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a Po…
CVE-2013-1064 medium 4.6 FIX debian debianubuntu ubuntu canonical 13y ago apt-xapian-index before 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restr…
CVE-2013-1063 medium 4.6 ubuntu ubuntu evan_dandrea 13y ago usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass i…
CVE-2013-1062 medium 4.6 ubuntu ubuntu michael_vogt 13y ago ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass in…
CVE-2013-1061 medium 4.6 FIX ubuntu ubuntudebian debian marc_deslauriers 13y ago dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authorit…
CVE-2013-5745 high 8.1 EXPFIX ubuntu ubuntudebian debian david_king 13y ago The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error …
CVE-2013-4222 medium 6.5 FIX debian debianubuntu ubuntufedora fedora openstackredhat 13y ago OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users …
CVE-2013-0211 medium 5.0 FIX debian debianubuntu ubuntususe suse libarchive 13y ago Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers …
CVE-2013-4296 medium 4.0 FIX ubuntu ubuntu rheldebian debian redhat 13y ago The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated u…
CVE-2013-4343 medium 6.9 FIX linux-kerneldebian debianubuntu ubuntu 13y ago Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap i…
CVE-2013-1060 medium 6.9 ubuntu ubuntu 13y ago A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd direc…
CVE-2013-4202 medium 4.3 FIX debian debianubuntu ubuntu openstack 13y ago OpenStack Cinder Denial of Service using XML entities
CVE-2013-4130 medium 5.0 FIX ubuntu ubuntudebian debian spice_project 13y ago The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attack…
CVE-2013-2145 medium 4.4 FIX ubuntu ubuntususe susedebian debian perlmonks 13y ago The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special u…
CVE-2013-1872 medium 6.8 FIX ubuntu ubuntu rhelsuse suse mesa3d 13y ago The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d g…
CVE-2013-2175 medium 5.0 FIX ubuntu ubuntudebian debian redhathaproxy 13y ago HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (ne…
CVE-2013-4248 medium 4.3 ubuntu ubuntu rhel php 13y ago The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Na…
CVE-2013-4238 medium 4.3 FIX slesubuntu ubuntususe suse python 13y ago The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, w…
CVE-2013-2132 medium 4.3 FIX ubuntu ubuntususe susedebian debian mongodb 13y ago bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) vi…
CVE-2013-2126 high 7.5 FIX debian debianubuntu ubuntususe suse libraw 13y ago Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and po…
CVE-2013-4124 medium 6.0 EXPFIX ubuntu ubuntu rhelfedora fedora samba 13y ago Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (…
CVE-2013-2174 medium 6.8 FIX debian debianubuntu ubuntususe suse haxx 13y ago Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possib…
CVE-2013-2112 high 7.8 FIX ubuntu ubuntususe susedebian debian apachecollabnet 13y ago The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
CVE-2013-1968 medium 5.5 FIX ubuntu ubuntususe susedebian debian apachecollabnet 13y ago Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
CVE-2013-4002 high 7.1 linux-kernelubuntu ubuntususe suse ibmoracleapache 13y ago Missing XML Validation in Apache Xerces2
CVE-2013-4668 medium 5.0 FIX debian debianubuntu ubuntu file_roller_project 13y ago Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a craft…
CVE-2013-3809 medium 4.0 ubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to …
CVE-2013-3804 medium 4.0 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unk…
CVE-2013-3802 medium 4.0 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unk…
CVE-2013-3793 medium 4.0 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related …
CVE-2013-3783 medium 4.0 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser.
CVE-2013-1943 high 7.8 7.8 FIX linux-kerneldebian debian rhel 13y ago The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows loca…
CVE-2013-1896 medium 4.3 FIX debian debian rhelubuntu ubuntu apacheredhat 13y ago mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a M…
CVE-2013-1059 high 7.8 FIX debian debian linux-kernelubuntu ubuntu 13y ago net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an…
CVE-2013-2064 medium 6.8 FIX debian debiansuse susefedora fedora oraclex 13y ago Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
CVE-2013-1987 medium 6.8 FIX debian debiansuse suseubuntu ubuntu x 13y ago Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters,…
CVE-2013-1981 medium 6.8 FIX debian debianubuntu ubuntu x 13y ago Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFon…
CVE-2013-1862 medium 5.1 FIX debian debiansuse suse rhel apacheredhatoracle 13y ago mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to exec…
CVE-2013-2852 medium 7.9 EXPFIX debian debianubuntu ubuntu linux-kernel 13y ago Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain pr…
CVE-2002-2443 medium 5.0 FIX debian debiansuse susefedora fedora mit 13y ago schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial o…
CVE-2007-6746 medium 5.8 FIX ubuntu ubuntudebian debian canonical 13y ago telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of t…
CVE-2013-2021 medium 4.3 FIX debian debianubuntu ubuntususe suse clamav 13y ago pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
CVE-2013-2020 medium 5.0 FIX debian debianubuntu ubuntususe suse clamav 13y ago Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in…
CVE-2013-0306 medium 5.0 FIX ubuntu ubuntudebian debian djangoproject 13y ago The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of ser…
CVE-2013-0305 medium 4.0 FIX ubuntu ubuntudebian debian djangoproject 13y ago The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated a…
CVE-2013-1944 medium 5.0 FIX debian debianubuntu ubuntu haxx 13y ago The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix…
CVE-2013-1927 medium 6.8 FIX debian debiansuse suseubuntu ubuntu redhat 13y ago The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
CVE-2013-1926 medium 5.8 FIX debian debiansuse suseubuntu ubuntu redhat 13y ago The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensi…
CVE-2013-0338 medium 4.3 FIX suse suseubuntu ubuntudebian debian xmlsoft 13y ago libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and …
CVE-2013-1901 medium 4.0 ubuntu ubuntu postgresql 13y ago PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) …
CVE-2013-1900 high 8.5 ubuntu ubuntu postgresql 13y ago PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated us…
CVE-2013-1899 medium 7.5 EXP ubuntu ubuntu postgresql 13y ago Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remot…
CVE-2013-0800 medium 6.8 ubuntu ubuntudebian debiansuse suse mozilla 13y ago Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird be…
CVE-2013-0791 medium 5.0 FIX ubuntu ubuntudebian debian rhel mozillaoracle 13y ago The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x…
CVE-2012-6129 high 7.5 FIX ubuntu ubuntufedora fedoradebian debian transmissionbt 13y ago Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute ar…
CVE-2013-1799 medium 4.3 FIX debian debianubuntu ubuntu gnome 13y ago Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-…
CVE-2013-0240 medium 4.3 FIX debian debianubuntu ubuntu gnome 13y ago Gnome Online Accounts (GOA) 3.4.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.5, does not properly validate SSL certificates when creating accounts such as Windows Live and Facebook accounts, which all…
CVE-2013-1861 medium 6.0 EXP ubuntu ubuntudebian debian rhel mariadboracle 13y ago MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers…
CVE-2013-0454 medium 4.0 FIX slesubuntu ubuntudebian debian sambaibm 13y ago The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS sh…
CVE-2013-0335 medium 6.0 FIX ubuntu ubuntudebian debian openstack 13y ago OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM t…
CVE-2013-1860 medium 6.9 FIX ubuntu ubuntudebian debian linux-kernel 13y ago Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system c…
CVE-2013-1052 high 7.2 ubuntu ubuntu 13y ago pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.